Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,899
Mitigations
Mitigation rules
16,068
No official patch
13,136
In triage
1,194
Published soon
56
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Custom Fields Account Registration For Woocommerce
< 1.4
Unauthenticated Privilege Escalation vulnerability
9.8
2 minutes ago
Advanced Responsive Video Embedder
10.8.7
Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter vulnerability
9.8
13 minutes ago
MemberGlut
< 1.1.5
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
28 minutes ago
Printcart Web to Print Product Designer for WooCommerce
< 2.5.3
Unauthenticated Arbitrary File Read and Server-Side Request Forgery vulnerability
8.6
34 minutes ago
MainWP Child
< 6.1.2
Unauthenticated Administrator Authentication Bypass vulnerability
9.8
43 minutes ago
style-dictionary
>= 4.3.0, < 5.4.4
Prototype Pollution in convertTokenData utility function
8.8
8 hours ago
@hypequery/clickhouse
< 2.0.2
NPM: @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
9.8
9 hours ago
@nocobase/plugin-collection-sql
< 2.0.62
NPM: NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
6.8
10 hours ago
qti-neon
1.0.0
NPM: QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
8.6
14 hours ago
@novu/application-generic
< 3.17.0
NPM: @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
6.8
16 hours ago
@wakaru/cli
>= 1.0.0, < 1.4.0
NPM: @wakaru/cli arbitrary file write during bundle unpack
7.1
16 hours ago
FundEngine
<= 1.7.8
Broken Access Control vulnerability
6.5
2 days ago
Booking Calendar
<= 11.4.2
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg
<= 1.5.1
Cross Site Scripting (XSS) vulnerability
6.5
2 days ago
Contact Form 7 – PayPal & Stripe Add-on
< 2.5
Open Redirect vulnerability
4.7
2 days ago
Download Manager
< 3.3.62
Unauthorized Protected File Download vulnerability
3.1
2 days ago
Smart Manager
< 8.92.0
Contributor+ Stored XSS vulnerability
6.5
2 days ago
ChatBot
< 8.5.2
Admin+ Second-Order SQL Injection vulnerability
3.8
2 days ago
The Events Calendar
< 6.16.5.1
Unauthenticated Event Aggregator Import Status Manipulation vulnerability
5.3
2 days ago
Advanced Ads
< 2.0.23
Contributor+ Stored XSS vulnerability
6.5
2 days ago
Load more